Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area where our services are offered, and it is intended to meet the requirements of the General Data Protection Regulation (GDPR). By using our services, you acknowledge that your personal data may be processed in accordance with this Policy.
1. Data We Collect
We collect and process only the personal data necessary for specific, explicit, and legitimate purposes. Depending on how you interact with us, we may collect the following categories of data:
- Identity data such as your name, title, and similar identifiers.
- Contact data such as billing address, delivery address, and other communication details.
- Transaction data such as details about purchases, services requested, payments, and related records.
- Technical data such as device information, browser type, operating system, and log data.
- Usage data such as information about how you interact with services, preferences, and service activity.
- Communication data such as messages, inquiries, complaints, and feedback you send to us.
- Marketing preferences including whether you have opted in or out of communications, where permitted by law.
We do not intentionally collect special category data unless it is necessary and we have a lawful basis to do so. Where such data is collected, we apply stricter safeguards and process it only when allowed under the GDPR.
2. How We Use Personal Data
We use personal data for the following purposes:
- To provide and manage our services.
- To process transactions and maintain accurate records.
- To communicate with you about service updates, requests, or support matters.
- To improve, monitor, and secure our services.
- To comply with legal obligations, regulatory requirements, and lawful requests.
- To prevent fraud, misuse, and unauthorized access.
- To send marketing communications where permitted and where you have not opted out.
We only use your data in ways that are compatible with the original purpose for which it was collected, unless we have a lawful basis to do otherwise.
3. Lawful Basis for Processing
Under the GDPR, we rely on one or more of the following lawful bases when processing personal data:
Performance of a Contract
We process data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We may process data where required to comply with applicable laws, regulations, court orders, tax rules, or other legal duties.
Legitimate Interests
We may process data when it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include improving services, detecting fraud, securing systems, and administering business operations.
Consent
Where required by law, we process data based on your consent. If we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Data Sharing and Processors
We may share personal data with trusted third parties that act as data processors or, in some cases, independent controllers. These parties are bound by appropriate contractual obligations and are only permitted to process data in accordance with our instructions or applicable legal requirements.
Processors may include:
- IT and cloud service providers that host, store, or support our systems.
- Payment service providers that process financial transactions securely.
- Analytics and performance providers that help us understand service usage and improve operations.
- Professional advisers such as auditors, legal advisers, and compliance consultants.
- Administrative or operational service providers that help us deliver services effectively.
We ensure that all processors offer sufficient guarantees to implement appropriate technical and organizational measures. Where data is transferred outside the European Economic Area, we take steps to ensure an adequate level of protection, such as relying on approved safeguards or adequacy decisions where applicable.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting obligations. Retention periods are determined by the nature of the data, the purpose of processing, and applicable legal requirements.
In general, we consider the following factors when determining retention periods:
- The duration of our relationship with you.
- Whether we are subject to statutory retention obligations.
- Whether the data is needed to resolve disputes or enforce agreements.
- Whether retention is necessary for security, fraud prevention, or compliance purposes.
When personal data is no longer required, we will delete it securely or anonymize it so that it can no longer identify you. In some cases, data may be retained in archived form where required by law or for legitimate business needs.
6. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, monitoring, and staff training.
While we take reasonable steps to protect your data, no system can be guaranteed to be completely secure. We therefore encourage all users to take appropriate precautions when sharing personal information.
7. Your Rights Under GDPR
Depending on your circumstances and applicable law, you have the following rights in relation to your personal data:
- Right of access – to request confirmation of whether we process your data and to obtain a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restriction – to request that we limit processing in certain situations.
- Right to data portability – to receive data you provided in a structured, commonly used, and machine-readable format, where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – to withdraw consent where processing is based on consent.
- Right to lodge a complaint – to complain to a supervisory authority if you believe your rights have been infringed.
We may need to verify your identity before responding to a rights request. In some cases, rights may be limited by legal obligations or legitimate grounds for retaining or processing data.
8. Children’s Data
Our services are not intended for children where parental consent is required by law. We do not knowingly collect personal data from children without the appropriate legal basis. If we become aware that such data has been collected without proper authorization, we will take reasonable steps to delete it.
9. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal effects or similarly significant effects, unless permitted by law and subject to appropriate safeguards. If such processing is used, we will provide meaningful information about the logic involved and the possible consequences, where required.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. Any revised version will apply from the date it is made available. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
11. Additional Information
This Privacy Policy should be read together with any other notices we provide at the point of data collection. If any part of this Policy is found to be inconsistent with applicable data protection law, the law will prevail to the extent of that inconsistency. Nothing in this Policy limits your statutory rights under the GDPR.
By using our services in the area covered by this Policy, you acknowledge that your personal data may be processed as described above, subject always to applicable data protection laws and the safeguards we apply.
